2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-42924MEDIUM6.1SAP S/4HANA landscape SAP E-Recruiting BSP allows an unauthenticated attacker to craft malicious links, when clicked the...
CVE-2025-42919MEDIUM5.3Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could b...
CVE-2025-42899MEDIUM4.3SAP S4CORE (Manage journal entries) does not perform necessary authorization checks for an authenticated user resulting ...
CVE-2025-42897MEDIUM5.3Due to information disclosure vulnerability in anonymous API provided by SAP Business One (SLD), an attacker with normal...
CVE-2025-42895MEDIUM6.9Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally a...
CVE-2025-42894MEDIUM6.8Due to a Path Traversal vulnerability in SAP Business Connector, an attacker authenticated as an administrator with adja...
CVE-2025-42893MEDIUM6.1Due to an Open Redirect vulnerability in SAP Business Connector, an unauthenticated attacker could craft a malicious URL...
CVE-2025-42892MEDIUM6.8Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative ac...
CVE-2025-42889MEDIUM5.4SAP Starter Solution allows an authenticated attacker to execute crafted database queries, thereby exposing the back-end...
CVE-2025-42888MEDIUM5.5SAP GUI for Windows may allow a highly privileged user on the affected client PC to locally access sensitive information...
CVE-2025-42886MEDIUM6.1Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an unauthenticated attacker could...
CVE-2025-42885MEDIUM5.8Due to missing authentication, SAP HANA 2.0 (hdbrss) allows an unauthenticated attacker to call a remote-enabled functio...
CVE-2025-42884MEDIUM6.5SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject JNDI environment properties or pass a URL u...
CVE-2025-42882MEDIUM4.3Due to a missing authorization check in SAP NetWeaver Application Server for ABAP, an authenticated attacker with basic ...
CVE-2025-31719MEDIUM5.1In TEE EcDSA algorithm, there is a possible memory consistency issue. This could lead to generated incorrect signature r...
CVE-2025-64529MEDIUM6.5SpiceDB is an open source database system for creating and managing security-critical application permissions. In versio...
CVE-2025-64504MEDIUM5Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2...
CVE-2025-64502MEDIUM6.9Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `exp...
CVE-2025-64167MEDIUM6.1Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-sit...
CVE-2025-63397MEDIUM6.5Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence ...
CVE-2025-62780MEDIUM5.4changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in cha...
CVE-2025-49145MEDIUM6.5Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough ri...
CVE-2025-63617MEDIUM6.5ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulne...
CVE-2025-63296MEDIUM6.5KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot...
CVE-2025-48878MEDIUM4.3Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now